INC Ransomware Group Exploits SonicWall Flaws in Global Attacks
AI-generated from multiple sources. Verify before acting on this reporting.
A coordinated ransomware campaign targeting private sector and government organizations across five nations has been linked to the exploitation of critical vulnerabilities in SonicWall network appliances. The attacks, attributed to the INC ransomware group and a threat actor designated as UTA0533, began on August 3, 2026.
Security researchers identified that attackers leveraged two newly disclosed flaws, cataloged as CVE-2026-15409 and CVE-2026-15410, affecting the SonicWall SMA1000 series. The vulnerabilities allowed threat actors to compromise firewalls without authentication, gaining unauthorized access to internal networks in the United States, Australia, the United Arab Emirates, Colombia, and Switzerland.
The primary objective of the intrusion was credential harvesting from compromised appliances. Once inside the network perimeter, attackers deployed malicious files designed to encrypt critical data systems for extortion purposes. The campaign represents a significant escalation in targeting infrastructure security devices, moving beyond traditional endpoints to compromise the very gateways protecting organizational networks.
Affected entities include municipal government bodies and private enterprises that rely on SonicWall hardware for their primary internet filtering and firewall operations. In several instances within the United States and Australia, network outages were reported shortly after initial access was gained, coinciding with the deployment of ransomware payloads. The attacks have forced many organizations to isolate affected systems, disrupting daily operations while incident response teams work to contain the spread.
SonicWall has acknowledged the existence of the vulnerabilities in its SMA1000 line and is working on patches for CVE-2026-15409 and CVE-2026-15410. The company advises administrators to apply updates immediately or implement temporary workarounds involving strict access controls until a fix is available. Despite these warnings, the rapid pace of exploitation suggests that attackers have been actively scanning for unpatched devices since the vulnerabilities were first identified.
The involvement of UTA0533 alongside the INC group indicates potential collaboration between distinct threat actors or the use of shared infrastructure to facilitate the campaign. While INC is known for its aggressive extortion tactics, including double and triple ransom demands, this specific operation focused heavily on initial access via the compromised appliances before deploying encryption tools.
Questions remain regarding the full scope of data exfiltration during these incidents. It is unclear whether attackers successfully harvested sensitive credentials from all targeted organizations or if they were limited to system-level access in some cases. Additionally, investigators are determining how many other global entities may have been breached but not yet reported. As patches roll out and affected networks come back online, the focus shifts to assessing long-term damage and preventing future exploitation of similar supply chain weaknesses.